Abstract— This research introduces a Blockchain-based Decentralized Application designed to address these issues. Leveraging Ethereum smart contracts and decentralized storage via IPFS, the application ensures secure peer-to-peer communication, immutable data storage, and enhanced transparency. By eliminating the need for centralized intermediaries, the Blockchain-based Decentralized Application empowers users, prioritizes data privacy, and fosters trust. This research introduces a Blockchain-based Decentralized Application designed to address these issues. Leveraging Ethereum smart contracts and decentralized storage via IPFS, the application ensures secure peer-to-peer communication, immutable data storage, and enhanced transparency. By eliminating the need for centralized intermediaries, the Blockchain-based Decentralized Application empowers users, prioritizes data privacy, and fosters trust. Index Terms—Distributed Ledger Technology(DLT), Smart Contracts, InterPlanetary File System(IPFS), Cryptographic Security.
A novel electronic voting system (EVS) was developed by integrating blockchain technology and advanced facial recognition to enhance electoral security, transparency, and accessibility.The system integrates a public, permissionless blockchain-specifically the Ethereum platform-to ensure end-to-end transparency and immutability throughout the voting lifecycle.To reinforce identity verification while preserving voter privacy, a facial recognition technology based on the ArcFace algorithm was employed.This biometric approach enables secure, contactless voter authentication, mitigating risks associated with identity fraud and multiple voting attempts.The confluence of blockchain technology and facial recognition in a unified architecture was shown to improve system robustness against tampering, data breaches, and unauthorized access.The proposed system was designed within a rigorous research framework, and its technical implementation was critically assessed in terms of security performance, scalability, user accessibility, and system latency.Furthermore, potential ethical implications and privacy considerations were addressed through the use of decentralized identity management and encrypted biometric data storage.The integration strategy not only enhances the verifiability and auditability of election outcomes but also promotes greater inclusivity by enabling remote participation without compromising system integrity.This study contributes to the evolving field of electronic voting by demonstrating how advanced biometric verification and distributed ledger technologies can be synchronously leveraged to support democratic processes.The findings are expected to inform future deployments of secure, accessible, and transparent electoral platforms, offering practical insights for governments, policymakers, and technology developers aiming to modernize electoral systems in a post-digital era.
This study explores the macroeconomic factors driving cryptocurrency price fluctuations, focusing on Bitcoin and Ethereum using the Random Forest machine learning model. It analyzes daily data from 2015 to 2025, incorporating key economic and financial indicators such as the S&P 500, NASDAQ, Treasury yield spreads, Federal Funds Rate, long-term Treasury rates, inflation, Brent oil prices, major exchange rates, and the Volatility Index. Separate predictive models for Bitcoin and Ethereum achieved high accuracy (R² = 0.999 and R² = 0.995, respectively), demonstrating the model's strong forecasting capability. The findings reveal that cryptocurrencies are increasingly influenced by traditional financial markets, particularly US stock indices, highlighting their integration into the global economic system. Bitcoin emerged as relatively stable and less sensitive to monetary policy shifts, functioning as a speculative hedge. In contrast, Ethereum showed greater sensitivity to liquidity and interest rate variables due to its linkage with decentralized finance applications. The study concludes that machine learning methods, combined with traditional macroeconomic indicators, can effectively explain and predict cryptocurrency market behavior, offering a foundation for developing new hybrid economic models tailored to the unique nature of digital assets.
We introduce EtherBee, a global dataset integrating detailed Ethereum node metrics, network traffic metadata, and honeypot interaction logs collected from ten geographically diverse vantage points over three months. By correlating node data with granular network sessions and security events, EtherBee provides unique insights into benign and malicious activity, node stability, and network-level threats in the Ethereum peer-to-peer network. A case study shows how client-based optimizations can unintentionally concentrate the network geographically, impacting resilience and censorship resistance. We publicly release EtherBee to promote further investigations into performance, reliability, and security in decentralized networks.
We believe that leveraging real-time blockchain operational data is of particular interest in the context of the current rapid expansion of rollup networks in the Ethereum ecosystem. Given the compatible but also competing ground that rollups offer for applications, stream-based monitoring can be of use both to developers and to EVM networks governance. In this paper, we discuss this perspective and propose a basic monitoring pipeline.
Chitrita Devi, R. R. Shantha Spandana, G.V.T. Swapna, G Viswanath
This project provides a Cloud-Assisted Decentralized privacy-preserving Framework (CA-DPPF) that amalgamates cloud computing, blockchain generation, and IPFS to tackle the complexities of securely and efficaciously storing sensitive healthcare data. The framework utilizes ECDSA digital signatures and RSA encryption to assure strong person authentication and statistics safety, in accordance with present day developments in safeguarding healthcare information. IPFS is applied for scalable storage solutions, addressing the limitations of traditional centralized cloud services, as indicated in previous research. Blockchain era augments the system through supplying immutable document-preserving, mitigating the weaknesses of centralized systems. A rankings module is incorporated to guarantee the legitimacy of healthcare feedback, allowing people to assess doctors, with these checks securely documented on the blockchain to prevent manipulation. smart contracts, created in Solidity, enable secure transactions and govern user data at the Ethereum blockchain, making certain transparency and integrity in all interactions. The studies gives a spread that integrates the CHACHA20 encryption algorithm, strengthening computational efficiency and safety while complementing present encryption methods and improving usual system overall performance.
The reliability and precision of stock market forecasting are of paramount importance to investors, regulatory authorities, and financial institutions.Traditional centralized systems for data processing and model deployment have been found to suffer from critical vulnerabilities, including susceptibility to tampering, single points of failure, and a lack of verifiability.To address these limitations, a novel hybrid framework has been developed that integrates advanced deep learning models with decentralized blockchain infrastructure to ensure both predictive accuracy and data integrity in financial time series forecasting.Temporal dependencies in market dynamics are captured through the use of recurrent neural networks (RNNs) and long short-term memory (LSTM) architectures, which have been extensively trained to model non-linear and non-stationary behaviors in high-frequency financial data.In parallel, a private Ethereum-based blockchain has been deployed to record cryptographic hashes of input datasets, model parameters, and forecasting outputs, thereby ensuring transparency, auditability, and immutability across the data lifecycle.To enable computational scalability, deep learning operations have been executed off-chain, while on-chain mechanisms are utilized for secure checkpointing and traceability.Empirical validation has been conducted using real-time data from the Borsa stanbul (BIST), demonstrating significant improvements in forecasting accuracy when compared with baseline statistical and machine learning (ML) models.Moreover, the integration of blockchain technology has enabled a verifiable audit trail for all predictive operations, enhancing trust in the data pipeline without compromising computational efficiency.The proposed framework represents a significant advancement towards secure, transparent, and trustworthy artificial intelligence (AI) in financial forecasting, with potential implications for the broader decentralized finance (DeFi) ecosystem and regulatory-compliant AI deployments in capital markets.
With the rapid development of blockchain technology, various blockchain systems are exhibiting vitality and potential. As a representative of Blockchain 3.0, the EOS blockchain has been regarded as a strong competitor to Ethereum. Nevertheless, compared with Bitcoin and Ethereum, academic research and in-depth analyses of EOS remain scarce. To address this gap, this study conducts a comprehensive investigation of the EOS blockchain from five key dimensions: system architecture, decentralization, performance, smart contracts, and behavioral security. The architectural analysis focuses on six core components of the EOS system, detailing their functionalities and operational workflows. The decentralization and performance evaluations, based on data from the XBlock data-sharing platform, reveal several critical issues: low account activity, limited participation in the supernode election process, minimal variation in the set of block producers, and a substantial gap between actual throughput and the claimed million-level performance. Five types of contract vulnerabilities are identified in the smart contract dimension, and four mainstream vulnerability detection platforms are introduced and comparatively analyzed. In terms of behavioral security, four real-world attacks targeting the structural characteristics of EOS are summarized. This study contributes to the ongoing development of the EOS blockchain and provides valuable insights for enhancing the security and regulatory mechanisms of blockchain ecosystems.
Abstract: This e-commerce platform is specifically designed for agriculture-based trade, leveraging advanced blockchain technology and decentralized file storage to create a transparent, secure, and efficient marketplace for farmers, buyers, and suppliers. The platform utilizes Ganache, a simulation of Ethereum transactions, to ensure that all transactions are secure, immutable, and verifiable on the blockchain. The decentralized architecture is further enhanced with IPFS (Interplanetary File System), enabling farmers to securely store their product information, including images and descriptions, in a way that prevents alteration or loss. This ensures that the product listings are transparent and tamper-proof. The platform also incorporates cryptocurrency payments, enabling fast, secure, and borderless transactions between buyers and sellers. Utilizing smart contracts, the system automates payment flows based on predefined conditions, reducing the reliance on intermediaries and minimizing fraud risks. This fosters a trusted environment for agricultural trade, where both buyers and sellers can engage in transparent, efficient, and secure transactions. In addition to these core features, the platform includes a staking mechanism, allowing users to lock tokens to gain transaction privileges, influence governance decisions, and access premium features. This incentivizes long-term commitment and creates a sense of ownership within the platform. Active participants, such as those verifying transactions or maintaining data integrity, are rewarded with tokens, further promoting continuous engagement. The system also supports multilingual user interfaces, making it accessible to a global audience, and includes real-time updates for seamless interaction. Through transparent governance, decentralized voting, and economic incentives, the platform ensures a resilient and future-ready ecosystem for agro-commerce, empowering stakeholders to participate in decision-making and market dynamics, while addressing the challenges faced by farmers in accessing reliable markets and efficient payment systems.
Portfolio optimization is a fundamental problem in financial theory, aiming to balance risk and return in asset allocation. Traditional models, such as Mean–Variance optimization, are effective, but often fail to account for diversification adequately. This study introduces the Mean–Variance–Entropy (MVE) model, which integrates Tsallis entropy into the classic Mean–Variance framework to enhance portfolio diversification and risk management. Entropy, specifically second-order entropy, penalizes excessive concentration in the portfolio, encouraging a more balanced and diversified allocation of assets. The model is applied to a portfolio of five major cryptocurrencies: Bitcoin (BTC), Ethereum (ETH), Solana (SOL), Cardano (ADA), and Binance Coin (BNB). The performance of the MVE model is compared with that of the traditional Mean–Variance model, and results demonstrate that the entropy-enhanced model provides better diversification, although with a slightly lower Sharpe ratio. The findings suggest that while the entropy-adjusted model results in a slightly lower Sharpe ratio, it offers better diversification and a more resilient portfolio, especially in volatile markets. This study demonstrates the potential of incorporating entropy into portfolio optimization as a means to mitigate concentration risk and improve portfolio performance. The approach is particularly beneficial for markets such as cryptocurrency, where volatility and asset correlations fluctuate rapidly. This paper contributes to the growing body of literature on portfolio optimization by offering a more diversified, robust, and risk-adjusted approach to asset allocation
Abstract Blockchain technology is redefining the financial sector by enabling decentralized, transparent, and secure alternatives to legacy systems. While its potential to reduce costs, accelerate transactions, and enhance financial inclusion is widely acknowledged, challenges such as regulatory ambiguity, scalability limitations, and interoperability gaps impede mass adoption. This study employs a mixed-method approach—combining a systematic review of academic literature, industry reports, and case studies (Ethereum, Hyperledger, Ripple) with qualitative insights from fintech experts and quantitative data from a pilot project on cross-border transactions. Key findings reveal blockchain reduces transaction costs by 70%, slashes settlement times from days to minutes, and mitigates fraud through tamper-proof ledgers. Decentralized finance (DeFi) platforms democratize access to financial services, while smart contracts automate complex agreements. However, energy-intensive consensus mechanisms, fragmented regulations, and technical incompatibilities remain critical hurdles. The study concludes that blockchain’s transformative promise hinges on collaborative efforts among regulators, institutions, and technologists to address scalability, standardization, and compliance. Policy innovation, infrastructure modernization, and shifts toward sustainable protocols like Proof of Stake (PoS) are essential to unlock blockchain’s full potential in building an inclusive and efficient financial ecosystem. Keywords: Blockchain Technology, Decentralized Finance (DeFi), Smart Contracts, Financial Inclusion, Regulatory Compliance
This study examines and compares the effectiveness of GARCH (Generalized Autoregressive Conditional Heteroskedasticity) and EGARCH (Exponential GARCH) models in forecasting volatility across three distinct financial markets: cryptocurrencies, Indonesian stocks, and U.S. stocks. The research analyzes daily closing price data from April 2018 to September 2024, focusing on five major cryptocurrencies (Bitcoin, Ethereum, Tether, Binance Coin, and Ripple), five Indonesian blue-chip stocks (BBCA, BBRI, BYAN, BMRI, and TPIA), and five major U.S. stocks (Apple, Nvidia, Microsoft, Google, and Amazon). Using comparative analysis of ARCH(1), GARCH(1,1), and EGARCH(1,1,1) models, the study evaluates their predictive accuracy through multiple metrics including AIC, MAE, RMSE, and SMAPE. Results indicate that EGARCH(1,1,1) generally performs better for cryptocurrencies and U.S. stocks, while GARCH(1,1) shows superior performance for Indonesian stocks, suggesting that volatility patterns and optimal forecasting models vary across different market contexts.
This paper investigates the volatility dynamics and underlying long memory features of four major cryptocurrencies-Bitcoin, Ethereum, Litecoin, and Ripple-which were selected due to their high liquidity, large trading volumes, and historical significance in the digital asset market. The long-range dependence exhibited in cryptocurrency markets is often overlooked. However, based on the strong evidence of persistent dependence in the return series, we adopt advanced volatility models that are capable of accommodating high volatility and heavy-tails, as well as the long memory properties of cryptocurrencies. Specifically, we employ long-memory extensions of the GAS (Long memory GAS) and GARCH (Fractionally Integrated Asymmetric Power ARCH) models, integrating heavy-tailed innovation distributions: the Generalized Hyperbolic Distribution (GHD) and Generalized Lambda Distribution (GLD). Standard GARCH and GAS models are included as benchmarks. The performance of the models are assessed using Value-at-Risk (VaR) estimation, backtesting (in-sample and out-of-sample) and volatility forecasting metrics. The results indicate that long memory models, particularly the FIAPARCH model, consistently outperforms the standard GAS and GARCH models in capturing tail risk and the volatility persistence. These findings emphasize the critical role of long memory in modeling the risk of cryptocurrencies, indicating that accounting for volatility persistence can significantly enhance the accuracy of risk estimates and strengthen risk management practices.
Pietro Saggese, Michael Fröwis, Stefan Kitzler, Bernhard Haslhofer · 5 authors
Total Value Locked (TVL) aims to measure the aggregate value of cryptoassets deposited in Decentralized Finance (DeFi) protocols. Although blockchain data is public, the way TVL is computed is not well understood. In practice, its calculation on major TVL aggregators relies on self-reports from community members and lacks standardization, making it difficult to verify published figures independently. We thus conduct a systematic study on 939 DeFi projects deployed in Ethereum. We study the methodologies used to compute TVL, examine factors hindering verifiability, and ultimately propose standardization attempts in the field. We find that 10.5% of the protocols rely on external servers; 68 methods alternative to standard balance queries exist, although their use decreased over time; and 240 equal balance queries are repeated on multiple protocols. These findings indicate limits to verifiability and transparency. We thus introduce ``verifiable Total Value Locked'' (vTVL), a metric measuring the TVL that can be verified relying solely on on-chain data and standard balance queries. A case study on 400 protocols shows that our estimations align with published figures for 46.5% of protocols. Informed by these findings, we discuss design guidelines that could facilitate a more verifiable, standardized, and explainable TVL computation.
Aikaterini-Panagiota Stouka, Julian Ma, Thomas Thiery
Transaction Fee Mechanism (TFM) design in blockchain protocols has gained significant attention following the pioneering work of Roughgarden [EC' 21], which established a formal framework for analyzing user and block proposer incentives under various Transaction Fee Mechanisms, including Ethereum's current fee mechanism EIP-1559. However, the original TFM framework and follow-up TFM works overlook the critical challenge of censorship resistance-specifically in the presence of an external malicious actor who is willing to bribe the proposer to censor a transaction. In this paper, we extend the Roughgarden's framework to capture censorship resistance under bribery attacks via a Bayesian game, where a strategic block proposer's "type" is determined by a bribe function from an external malicious actor. Under this framework, the definition of a standard TFM is extended to a bribery-aware TFM. This technique is broadly applicable to analyze censorship resistance under bribery attacks of both single and multiple proposer protocols within the original TFM scope. We choose to utilize it to evaluate the incentive compatibility and censorship resistance of several TFMs within the context of a multiple proposer protocol called Fork-Choice Enforced Inclusion Lists (FOCIL). FOCIL represents a critical evolution in the Ethereum roadmap, serving as the consensus and censorship resistance flagship for the upcoming Hegota hard fork. It aims to bolster Ethereum's censorship resistance by enabling multiple proposers to contribute to block construction. While recent works such as Garimidi et al.[FC' 25] have extended the TFM framework to multiple proposer settings, they do not aim to capture censorship under bribery attacks and they are not compatible with the unique hierarchical structure of FOCIL.
Hiago Vinícius Benedito dos Santos, Raissa Rosa dos Santos Januario, Ravelly Carvalho Zanatta, Saulo Neves Matos · 5 authors
In recent years, blockchain technology has established itself as an effective, secure, and transparent data storage solution. In this context, smart contracts play a fundamental role by enabling the automated execution of agreements without intermediaries. With the advancement of language models, the opportunity to automatically generate these contracts has emerged, raising concerns about their reliability and potential vulnerabilities. This article proposes a comparative analysis of the available language models for developing smart contracts using Ethereum Virtual Machine’s contracts as a case study. Experiments were made using various Large language models using different metrics to evaluate the susceptibility to vulnerabilities and computational cost. After comparing various models, ChatGPT appears to be the most suitable for generating smart contracts due to its higher compilation rate and, consequently, a larger sample size, despite detecting more vulnerabilities.
Carlos Melo, José Miqueias, Glauber Dias Gonçalves, Francisco Airton Silva · 6 authors
Embora a transição da plataforma Ethereum para Proof-of-Stake e o surgimento de sidechains ofereçam soluções parciais para os problemas de escalabilidade, essas abordagens apresentam trade-offs entre segurança e complexidade de implementação. Para mitigar esses desafios, os ZK-Rollups surgiram como soluções de escalabilidade de Layer-2, combinando computação off-chain com verificação on-chain, garantindo segurança e descentralização na plataforma Ethereum. Este artigo propõe uma abordagem baseada em Redes de Petri Estocásticas para avaliar a viabilidade dos ZK-Rollups, considerando os principais fatores que impactam métricas de desempenho essenciais, como vazão e latência. Também analisamos a relação entre custo e benefício, incluindo o custo médio por transação e como este é impactado pelas métricas de desempenho. Os resultados mostram que uma maior adoção de transações na Layer-2 pode aumentar a vazão do sistema em até 20%, passando de 85 tps em um ambiente sem Layer-2 para 105 tps quando 90% das transações seguem por esse caminho. Por outro lado, a latência pode sofrer um aumento superior a 100% com a utilização de batches maiores na Layer-2.
Jefferson Celeiro Sousa, Bruno Evaristo, Antonio Mateus de Sousa, Ismael Ávila
Este artigo apresenta uma avaliação de performance de contratos inteligentes voltados à gestão de identidades digitais descentralizadas em redes blockchain baseadas em Ethereum. A análise foca em operações fundamentais do ciclo de vida de identidades, como criação, atualização, definição de esquemas de credenciais e controle de revogação, implementadas em contratos Solidity. Foram considerados dois contextos de execução: um ambiente com Hyperledger Besu operando em modo permissionado, e uma referência ao modelo tradicional Hyperledger Indy. Os testes foram conduzidos em rede privada simulando diferentes níveis de carga e configurações de consenso. As métricas avaliadas incluem tempo de resposta, vazão, uso de recursos (CPU e memória) e escalabilidade. Os resultados fornecem subsídios para a escolha de arquiteturas eficientes para soluções de identidade digital baseadas em SSI (Self-Sovereign Identity) e Ethereum, especialmente em cenários corporativos ou regulados.
Josué N. Campos, I. R. de Oliveira, Alexandre Fontinele, Glauber Dias Gonçalves · 6 authors
A Máxima Extração de Valor em Blocos (MEV) surgiu como uma questão de extrema importância, particularmente no ecossistema Ethereum DeFi. As práticas de MEV permitem que os traders maximizem seus lucros ao reordenar, inserir ou bloquear transações dentro de um bloco. Recentemente, a rede Ethereum implementou o Paradigma de Separação Proponente-Construtor (PBS), dividindo a função dos mineradores em nós construtores e validadores. Apesar deste novo design, o fenômeno MEV permanece. Neste artigo, investigamos o ataque sanduíche, uma prática especial de MEV baseada na manipulação de preços por meio de técnicas de front-running na rede Ethereum sob o paradigma PBS. Nossa análise abrangeu mais de 1 milhão de blocos ao longo de 2023, onde identificamos aproximadamente 1,5 milhão de ataques sanduíche, com um lucro médio de US$ 3,2 mil para os atacantes. Nossos resultados mostram que o PBS contribuiu para encorajar as atividades de sanduíche, uma vez que os atacantes geralmente pagam as taxas mais altas aos construtores de blocos, cerca de 60% dos blocos, de acordo com nossas medições. Além disso, identificamos que poucos construtores se beneficiam dos ataques sanduíche. Neste caso, apenas 4 nós construtores receberam mais de 70% das taxas dos atacantes em 2023.
S. M. Dilip Kumar, Namrta Tanwar, Namrta Tanwar, Aakarsh Chandna · 5 authors
The blockchain technology has disrupted the earlyage digital banking through concepts like bitcoin and ether [1,3].In this study, some major elements of the blockchain technology are examined-decentralized networks, smart contracts, cryptographic techniques, and consensus mechanisms of Proof of Work and Proof of Stake usage-and understanding how they contribute to safe, peer-to-peer transactions without intermediaries [2,5].Bitcoin can do no more than about seven transactions a second (TPS) is a very paltry competition of an impressive 30 to 40 TPS of Ethereum.This depicts the ongoing scalability challenges that need to be tackled by initiatives linked with Ethereum 2.0 and the Lightning Network [4,9].While most industries, apart from banking, have effectively made their blockchain applications and transparency useful-Supply Chain Management, Healthcare, and DeFi-currently poses challenges of transaction speed limitations, the vagueness of regulations, and energy consumption by mining [8].Emerging trends include Non-Fungible Tokens (NFTs), Central Bank Digital Currencies (CBDCs), and privacy enhanced through zero-knowledge proofs.There is hope for excellent feedback on the future of the blockchain from these and other initiatives yet to come into reality.
BADADHE SHIVAJI, VENKATESH IYER, SAMI SHAIKH, ARUN GHANDAT
The real estate sector grapples with the persistent issues of inconsistent property appraisals, a lack of transparency in valuation methodologies, and a reliance on outdated pricing frameworks. This project introduces an innovative solution: a distributed ledger-based real estate valuation system. This system leverages self-executing digital agreements and spatial data analytics to deliver dynamic, transparent, and data-driven property assessments. By incorporating OpenStreetMap APIs, the system automates the acquisition of real-time data pertaining to proximate community resources, such as educational institutions, healthcare facilities, recreational spaces, and public transit networks. A weighted valuation algorithm processes this information to derive a contextual relevance score, quantifying the spatial influence and impact of these factors on property values. The computed scores, along with pertinent property details, are securely stored and managed on the Ethereum network via smart contracts, ensuring data integrity, immutability, and enhanced stakeholder trust. Furthermore, the system automates the entire valuation workflow through a Python-based backend, which serves as an intermediary between distributed ledger interactions and spatial data acquisition. Designed for scalability, transparency, and operational efficiency, this project aims to modernize conventional property valuation practices by addressing inherent inefficiencies and empowering stakeholders with access to reliable, up-to-the-minute valuation data. By redefining the paradigm of property value assessment, this system offers a transformative approach to real estate pricing, harmonizing cutting-edge distributed ledger technology with advanced spatial data analysis.
Sheng Zhang, Tan Kia Quang, Shen Wang, Shengchen Duan · 6 authors
Scam contracts on Ethereum have rapidly evolved alongside the rise of DeFi and NFT ecosystems, utilizing increasingly complex code obfuscation techniques to avoid early detection. This paper systematically investigates how obfuscation amplifies the financial risks of fraudulent contracts and undermines existing auditing tools. We propose a transfer-centric obfuscation taxonomy, distilling seven key features, and introduce ObfProbe, a framework that performs bytecode-level smart contract analysis to uncover obfuscation techniques and quantify obfuscation complexity via Z-score ranking. In a large-scale study of 1.03 million Ethereum contracts, we isolate over 3 000 highly obfuscated contracts and identify two scam archetypes, three high-risk contract categories, and MEV bots that employ a variety of obfuscation maneuvers such as inline assembly, dead code insertion, and deep function splitting. We further show that obfuscation substantially increases both the scale of financial damage and the time until detection. Finally, we evaluate SourceP, a state-of-the-art Ponzi detection tool, on obfuscated versus non-obfuscated samples and observe its accuracy drop from approximately 80 percent to approximately 12 percent in real-world scenarios. These findings highlight the urgent need for enhanced anti-obfuscation analysis techniques and broader community collaboration to stem the proliferation of scam contracts in the expanding DeFi ecosystem.
Xenia Hofmeier, Andrea Raguso, Ralf Sasse, Dennis Jackson · 5 authors
Aggregate signatures are digital signatures that compress multiple signatures from different parties into a single signature, thereby reducing storage and bandwidth requirements. BLS aggregate signatures are a popular kind of aggregate signature, deployed by Ethereum, Dfinity, and Cloudflare amongst others, currently undergoing standardization at the IETF. However, BLS aggregate signatures are difficult to use correctly, with nuanced requirements that must be carefully handled by protocol developers. In this work, we design the first models of aggregate signatures that enable formal verification tools, such as Tamarin and ProVerif, to be applied to protocols using these signatures. We introduce general models that are based on the cryptographic security definition of generic aggregate signatures, allowing the attacker to exploit protocols where the security requirements are not satisfied. We also introduce a second family of models formalizing BLS aggregate signatures in particular. We demonstrate our approach's practical relevance by modelling and analyzing in Tamarin a device attestation protocol called SANA. Despite SANA's claimed correctness proof, with Tamarin we uncover undocumented assumptions that, when omitted, lead to attacks.
Smart contracts have been a topic of interest in blockchain research and are a key enabling technology for Connected Autonomous Vehicles (CAVs) in the era of Web 3.0. These contracts enable trustless interactions without the need for intermediaries, as they operate based on predefined rules encoded on the blockchain. However, smart contacts face significant challenges in cross-contract communication and information sharing, making it difficult to establish seamless connectivity and collaboration among CAVs with Web 3.0. In this paper, we propose DeFeed , a novel secure protocol that incorporates various gas-saving functions for CAVs, originated from in-depth research into the interaction among smart contracts for decentralized cross-contract data feed in Web 3.0. DeFeed allows smart contracts to obtain information from other contracts efficiently in a single click, without complicated operations. We judiciously design and complete various functions with DeFeed , including a pool function and a cache function for gas optimization, a subscribe function for facilitating data access, and an update function for the future iteration of our protocol. Tailored for CAVs with Web 3.0 use cases, DeFeed enables efficient data feed between smart contracts underpinning decentralized applications and vehicle coordination. Implemented and tested on the Ethereum official test network, DeFeed demonstrates significant improvements in contract interaction efficiency, reducing computational complexity and gas costs. Our solution represents a critical step towards seamless, decentralized communication in Web 3.0 ecosystems.